Latest Vulnerabilities with Public Exploits
Updated 1h agoSearch and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.
53,633 results
Clear all
CVE-2025-66736
7.1
HIGH
1 PoC
EPSS 0.00
youlai-boot V2.21.1 - Auth Bypass
youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The importUsers function in SysUserController.java does not perform a permission check on the current user's identity, which may allow regular users to import user data into the database, resulting in an authorization bypass vulnerability.
CWE-284
Dec 22, 2025
CVE-2025-66735
7.5
HIGH
1 PoC
EPSS 0.00
youlai-boot 2.21.1 - Privilege Escalation
youlai-boot V2.21.1 is vulnerable to Incorrect Access Control. The getRoleForm function in SysRoleController.java does not perform permission checks, which may allow non-root users to directly access root roles.
CWE-284
Dec 22, 2025
CVE-2025-14673
7.3
HIGH
1 PoC
1 Writeup
EPSS 0.00
Gmg137 Snap7-rs < 1.142.1 - Memory Corruption
A vulnerability has been found in gmg137 snap7-rs up to 1.142.1. Affected is the function snap7_rs::client::S7Client::as_ct_write of the file /tests/snap7-rs/src/client.rs. The manipulation leads to heap-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CWE-122
Dec 14, 2025
CVE-2025-14672
7.3
HIGH
1 PoC
1 Writeup
EPSS 0.00
Gmg137 Snap7-rs < 1.142.1 - Memory Corruption
A flaw has been found in gmg137 snap7-rs up to 1.142.1. This impacts the function TSnap7MicroClient::opWriteArea of the file s7_micro_client.cpp. Executing a manipulation can lead to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.
CWE-122
Dec 14, 2025
CVE-2025-14538
3.5
LOW
1 PoC
EPSS 0.00
yangshare warehouseManager 1.1.0 - XSS
A security vulnerability has been detected in yangshare warehouseManager 仓库管理系统 1.1.0. This affects the function addCustomer of the file CustomerManageHandler.java. Such manipulation of the argument Name leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
CWE-79
Dec 11, 2025
CVE-2025-55471
7.5
HIGH
1 PoC
EPSS 0.00
youlai-boot <2.21.1 - Info Disclosure
Incorrect access control in the getUserFormData function of youlai-boot v2.21.1 allows attackers to access sensitive information for other users.
CWE-284
Nov 26, 2025
CVE-2025-55469
9.8
CRITICAL
1 PoC
EPSS 0.00
youlai-boot <2.21.1 - Privilege Escalation
Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and access the Administrator backend.
CWE-284
Nov 26, 2025
CVE-2025-46175
7.5
HIGH
1 PoC
EPSS 0.00
Ruoyi - Missing Authorization
Ruoyi v4.8.0 is vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the authRole method of SysUserController.java.
CWE-284
Nov 26, 2025
CVE-2025-56396
8.8
HIGH
1 PoC
EPSS 0.00
Ruoyi - Improper Access Control
An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department having higher rights than the active user.
CWE-284
Nov 26, 2025
CVE-2025-46174
7.5
HIGH
1 PoC
EPSS 0.00
Ruoyi - Missing Authorization
Ruoyi v4.8.0 vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the resetPwd Method of SysUserController.java.
CWE-284
Nov 26, 2025
CVE-2025-10993
4.7
MEDIUM
1 PoC
EPSS 0.00
MuYuCMS <2.7 - Code Injection
A security flaw has been discovered in MuYuCMS up to 2.7. Affected by this issue is some unknown functionality of the file /admin.php of the component Template Management. The manipulation results in code injection. It is possible to launch the attack remotely.
CWE-74
Sep 26, 2025
CVE-2025-56304
6.1
MEDIUM
1 PoC
Analysis
EPSS 0.00
Yzmcms < 7.3 - XSS
Cross-site scripting (XSS) vulnerability in YzmCMS thru 7.3 via the referer header in the register page.
CWE-79
Sep 23, 2025
CVE-2025-10787
6.3
MEDIUM
1 PoC
EPSS 0.00
MuYuCMS <2.7 - SSRF
A vulnerability was found in MuYuCMS up to 2.7. Impacted is an unknown function of the file /index/index.html of the component Add Fiend Link Handler. Performing manipulation of the argument Link URL results in server-side request forgery. The attack may be initiated remotely. The exploit has been made public and could be used.
CWE-918
Sep 22, 2025
CVE-2025-55849
8.4
HIGH
1 PoC
EPSS 0.00
WeiPHP <5.0 - SQL Injection
WeiPHP v5.0 and before is vulnerable to SQL Injection via the SucaiController.class.php file and the cancelTemplatee
CWE-89
Sep 08, 2025
CVE-2025-50902
8.8
HIGH
1 PoC
EPSS 0.00
old-peanut Open-Shop <1.0.0 - CSRF
Cross Site Request Forgery (CSRF) vulnerability in old-peanut Open-Shop (aka old-peanut/wechat_applet__open_source) thru 1.0.0 allows attackers to gain sensitive information via crafted HTTP Post message.
CWE-352
Aug 20, 2025
CVE-2025-5680
6.3
MEDIUM
1 PoC
EPSS 0.01
Tongzhouyun Agilebpm < 2.5.0 - Insecure Deserialization
A vulnerability classified as critical was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 2.5.0. Affected by this vulnerability is the function executeScript of the file /src/main/java/com/dstz/sys/rest/controller/SysScriptController.java of the component Groovy Script Handler. The manipulation of the argument script leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CWE-502
Jun 05, 2025
CVE-2025-5679
6.3
MEDIUM
1 PoC
EPSS 0.01
Tongzhouyun Agilebpm < 2.5.0 - Insecure Deserialization
A vulnerability classified as critical has been found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 2.5.0. Affected is the function parseStrByFreeMarker of the file /src/main/java/com/dstz/sys/rest/controller/SysToolsController.java. The manipulation of the argument str leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-502
Jun 05, 2025
CVE-2025-5569
6.3
MEDIUM
2 PoCs
NUCLEI
EPSS 0.01
IdeaCMS <1.8 - SQL Injection
A vulnerability was found in IdeaCMS up to 1.7 and classified as critical. This issue affects the function Article/Goods of the file /api/v1.index.article/getList.html. The manipulation of the argument Field leads to sql injection. The attack may be initiated remotely. Upgrading to version 1.8 is able to address this issue. The patch is named 935aceb4c21338633de6d41e13332f7b9db4fa6a. It is recommended to upgrade the affected component.
CWE-74
Jun 04, 2025
CVE-2025-5523
3.5
LOW
1 PoC
EPSS 0.00
enilu web-flash 1.0 - XSS
A vulnerability classified as problematic has been found in enilu web-flash 1.0. This affects the function fileService.upload of the file src/main/java/cn/enilu/flash/api/controller/FileController/upload of the component File Upload. The manipulation of the argument File leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CWE-94
Jun 03, 2025
CVE-2025-5522
7.3
HIGH
1 PoC
EPSS 0.00
bskms 蓝天幼儿园管理系统 - Auth Bypass
A vulnerability was found in jack0240 魏 bskms 蓝天幼儿园管理系统 up to dffe6640b5b54d8e29da6f060e0493fea74b3fad. It has been rated as critical. Affected by this issue is some unknown functionality of the file /sa/addUser of the component User Creation Handler. The manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
CWE-266
Jun 03, 2025